Skip to content
September 24, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Starland RAT Campaign by Russian-Speaking Actor UAT-11795 Targets Crypto Users in the US and Europe Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Cybercriminals

Starland RAT Campaign by Russian-Speaking Actor UAT-11795 Targets Crypto Users in the US and Europe

Do Son July 22, 2026 0
Read More Read more about Starland RAT Campaign by Russian-Speaking Actor UAT-11795 Targets Crypto Users in the US and Europe
Public PoC Exploit Released for fastjson 1.2.83 Remote Code Execution Flaw fastjson RCE vulnerability in versions 1.2.68 to 1.2.83 with public PoC exploit code
  • Vulnerability Report

Public PoC Exploit Released for fastjson 1.2.83 Remote Code Execution Flaw

Do Son July 22, 2026 0
Read More Read more about Public PoC Exploit Released for fastjson 1.2.83 Remote Code Execution Flaw
FreePBX Vulnerabilities Enable Unauthenticated RCE and Administrator Takeover FreePBX vulnerabilities enabling unauthenticated RCE and administrator takeover in UCP and missedcall
  • Vulnerability Report

FreePBX Vulnerabilities Enable Unauthenticated RCE and Administrator Takeover

Do Son July 22, 2026 0
Read More Read more about FreePBX Vulnerabilities Enable Unauthenticated RCE and Administrator Takeover
AppViewX Arms Enterprise CLM Teams for Post-Quantum Migration and AI Adoption in Latest Product Release PR_AppViewX_Arms_Enterprise_CLM_Teams_for_Post-Qua_1784554988mVnZWmnLOX
  • Press Release

AppViewX Arms Enterprise CLM Teams for Post-Quantum Migration and AI Adoption in Latest Product Release

cybernewswire July 22, 2026 0
Read More Read more about AppViewX Arms Enterprise CLM Teams for Post-Quantum Migration and AI Adoption in Latest Product Release
TTF Trap Campaign Hides a Low-Detection Lua Loader Inside Fake TrueType Font Files FSB Center 16 targeting vulnerable routers across critical infrastructure via weak SNMP
  • Malware

TTF Trap Campaign Hides a Low-Detection Lua Loader Inside Fake TrueType Font Files

Do Son July 22, 2026 0
Read More Read more about TTF Trap Campaign Hides a Low-Detection Lua Loader Inside Fake TrueType Font Files
CVE-2026-60206 (CVSS 9.9): Takeover Flaw Hits Oracle WebLogic Server Oracle WebLogic Server vulnerability chart highlighting CVE-2026-60206 with a CVSS 9.9 score enabling unauthenticated server takeover
  • Vulnerability Report

CVE-2026-60206 (CVSS 9.9): Takeover Flaw Hits Oracle WebLogic Server

Do Son July 22, 2026 0
Read More Read more about CVE-2026-60206 (CVSS 9.9): Takeover Flaw Hits Oracle WebLogic Server
IRGC Claims Strike on AWS Bahrain Data Center AWS Bahrain data center region ME-South-1 marked unavailable after claimed Iranian cruise missile strike
  • Technology

IRGC Claims Strike on AWS Bahrain Data Center

Do Son July 22, 2026 0
Read More Read more about IRGC Claims Strike on AWS Bahrain Data Center
Daxin Malware Resurfaces in Taiwan Alongside New Stupig Backdoor North Korean hackers behind open-source supply chain attacks on axios, debug, and chalk NPM packages
  • Malware

Daxin Malware Resurfaces in Taiwan Alongside New Stupig Backdoor

Do Son July 22, 2026 0
Read More Read more about Daxin Malware Resurfaces in Taiwan Alongside New Stupig Backdoor
Firefox Native Containers Arrive in Version 153 Firefox native containers in Firefox 153 showing color-coded container tabs for work, banking and shopping
  • Technology

Firefox Native Containers Arrive in Version 153

Do Son July 22, 2026 0
Read More Read more about Firefox Native Containers Arrive in Version 153
Gafgyt Botnet Hijacks Langflow AI Servers for DDoS Attacks Gafgyt botnet Langflow DDoS attack infection chain diagram
  • Malware

Gafgyt Botnet Hijacks Langflow AI Servers for DDoS Attacks

Do Son July 22, 2026 0
Read More Read more about Gafgyt Botnet Hijacks Langflow AI Servers for DDoS Attacks
OkoBot Framework Uses 20+ Modules to Steal Cryptocurrency Wallet Seed Phrases OkoBot framework cryptocurrency wallet theft infection chain diagram
  • Malware

OkoBot Framework Uses 20+ Modules to Steal Cryptocurrency Wallet Seed Phrases

Do Son July 22, 2026 0
Read More Read more about OkoBot Framework Uses 20+ Modules to Steal Cryptocurrency Wallet Seed Phrases
AccuKnox Wins Best AI Startup Award for Enterprise Agentic AI Security at BSides Bangalore bsides-AI-startup-award-768x480_1784697958MrhztSKZNH
  • Press Release

AccuKnox Wins Best AI Startup Award for Enterprise Agentic AI Security at BSides Bangalore

cybernewswire July 22, 2026 0
Read More Read more about AccuKnox Wins Best AI Startup Award for Enterprise Agentic AI Security at BSides Bangalore
Anthropic AI Copyright Lawsuit Reaches Historic $1.5 Billion Resolution Anthropic AI copyright lawsuit litigation documents and digital library data visualization
  • Technology

Anthropic AI Copyright Lawsuit Reaches Historic $1.5 Billion Resolution

Do Son July 22, 2026 0
Read More Read more about Anthropic AI Copyright Lawsuit Reaches Historic $1.5 Billion Resolution
OpenAI Autonomous Agent Escapes Sandbox to Breach Hugging Face OpenAI agent escape network architecture diagram showing custom sandbox breakout and autonomous Hugging Face cyberattack path.
  • Vulnerability Report

OpenAI Autonomous Agent Escapes Sandbox to Breach Hugging Face

Do Son July 22, 2026 0
Read More Read more about OpenAI Autonomous Agent Escapes Sandbox to Breach Hugging Face
WSUS Sync Timeouts: Microsoft Issues a Cleanup Fix WSUS sync timeouts causing failed Windows Update scans on enterprise Windows Server update servers
  • Windows

WSUS Sync Timeouts: Microsoft Issues a Cleanup Fix

Do Son July 22, 2026 0
Read More Read more about WSUS Sync Timeouts: Microsoft Issues a Cleanup Fix
Google Chrome Update Patches 12 High-Severity Security Flaws Chrome security update patching 12 high-severity vulnerabilities in Chrome 150
  • Vulnerability Report

Google Chrome Update Patches 12 High-Severity Security Flaws

Do Son July 22, 2026 0
Read More Read more about Google Chrome Update Patches 12 High-Severity Security Flaws
Vitest Flaw Rated CVSS 9.4 Hits an npm Package With 65 Million Weekly Downloads Vitest vulnerability in Browser Mode bypassing the file-access permission gate (CVSS 9.4)
  • Vulnerability Report

Vitest Flaw Rated CVSS 9.4 Hits an npm Package With 65 Million Weekly Downloads

Do Son July 22, 2026 0
Read More Read more about Vitest Flaw Rated CVSS 9.4 Hits an npm Package With 65 Million Weekly Downloads
How to Manage ESRS Metrics for Secure, Audit-Ready CSRD Reporting ste6
  • Technique

How to Manage ESRS Metrics for Secure, Audit-Ready CSRD Reporting

Do Son July 22, 2026 0
Read More Read more about How to Manage ESRS Metrics for Secure, Audit-Ready CSRD Reporting
How to Edit and Improve Photos with AI Tools 1
  • Technique

How to Edit and Improve Photos with AI Tools

Do Son July 22, 2026 0
Read More Read more about How to Edit and Improve Photos with AI Tools
SolarWinds Patches 15 Critical Serv-U Vulnerabilities Enabling Root Access SolarWinds Serv-U vulnerabilities enabling privilege escalation and remote code execution as root
  • Vulnerability Report

SolarWinds Patches 15 Critical Serv-U Vulnerabilities Enabling Root Access

Do Son July 21, 2026 0
Read More Read more about SolarWinds Patches 15 Critical Serv-U Vulnerabilities Enabling Root Access
snap-confine Flaw CVE-2026-8933 Lets Any User Get Root on Ubuntu CVE-2026-8933 is a snap-confine privilege escalation flaw. It gives any user root on default Ubuntu Desktop 26.04, 25.10, and 24.04. Update snapd now. #snapconfine #CVE20268933 #Ubuntu #PrivilegeEscalation #LPE #Linux #Qualys
  • Vulnerability Report

snap-confine Flaw CVE-2026-8933 Lets Any User Get Root on Ubuntu

Do Son July 21, 2026 0
Read More Read more about snap-confine Flaw CVE-2026-8933 Lets Any User Get Root on Ubuntu
CISA Adds Four Exploited Vulnerabilities to Its KEV Catalog CISA KEV catalog adding four known exploited vulnerabilities including WordPress and Langflow RCE
  • Vulnerability Report

CISA Adds Four Exploited Vulnerabilities to Its KEV Catalog

Do Son July 21, 2026 0
Read More Read more about CISA Adds Four Exploited Vulnerabilities to Its KEV Catalog
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-32996CVSS 7.3
    A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
    Admin intel📅 Updated: Sep 22, 2026
  • CVE-2026-7273CVSS 8.8
    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a...
    CISA KEV📅 Added to KEV: Sep 21, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-78312CVSS 9.1
    Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-78308CVSS 9.8
    Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-84502CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84719CVSS 9.9
    A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84474CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed...
    📅 Updated: Sep 24, 2026
  • CVE-2026-75884CVSS 9.1
    A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts...
    📅 Updated: Sep 24, 2026
  • CVE-2026-12564CVSS 9.6
    A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads...
    📅 Updated: Sep 24, 2026
  • CVE-2026-86708CVSS 10.0
    ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private...
    📅 Updated: Sep 24, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.